CVE-2026-90537
published 2026-09-12CVE-2026-90537: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that…
PriorityP353high8.2CVSS 3.1
AVNACLPRNUINSUCHILAN
EPSS
0.36%
27.6th percentile
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide daily token. Attackers can enumerate scheduler jobs, read private live titles and email addresses, and trigger email sending by supplying any valid daily token obtained from Live pages.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wwbn | avideo | <= c3edcc274c389816d434acadac07ee78eaf330c1 | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WWBN AVideo Scheduler Email sendEmail.json.php sendEmail daily token improper authorization
vuldb·2026-09-12·CVSS 8.2
CVE-2026-90537 [HIGH] WWBN AVideo Scheduler Email sendEmail.json.php sendEmail daily token improper authorization
A vulnerability, which was classified as critical, was found in WWBN AVideo. This issue affects the function sendEmail of the file plugin/Scheduler/sendEmail.json.php of the component Scheduler Email. Executing a manipulation of the argument daily token can lead to improper authorization.
This vulnerability is tracked as CVE-2026-90537. The attack can be launched remotely. No exploit exists.
It is advisable to implement a patch to correct this issue.
GHSA
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to acces
ghsa_unreviewed·2026-09-12
CVE-2026-90537 [HIGH] CWE-862 WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to acces
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide daily token. Attackers can enumerate scheduler jobs, read private live titles and email addresses, and trigger email sending by supplying any valid daily token obtained from Live pages.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-12
Published